1. Migration is not optional - SafetyNet is fully off. Google states on its deprecation timeline: "The SafetyNet Attestation API was deprecated in 2022 and fully turned down in January 2025. Developers should migrate to the Play Integrity API that consolidates multiple integrity offerings (including the SafetyNet Attestation integrity verdict) under a single API." Any surviving call now fails: "If you try to call the SafetyNet Attestation API, you will receive an error. The attest API returns a task that always invokes the onFailure listener with an ApiException and a status code of 7 (NETWORK_ERROR)." If you still ship a version that calls SafetyNet, instruct your users to update. (https://developer.android.com/privacy-and-security/safetynet/deprecation-timeline)
2. What the API actually verifies. "The Play Integrity API helps you check that user actions and server requests are coming from your genuine app, installed by Google Play, running on a genuine and certified Android device." It returns three core verdicts: accountDetails (unauthorized access - whether the user installed or paid for the app on Google Play), appIntegrity (code tampering - whether the binary is the unmodified one Google Play recognizes), and deviceIntegrity (risky devices and emulated environments - a genuine certified Android device or a genuine instance of Google Play Games for PC). Optional verdicts add MEETS_STRONG_INTEGRITY (recent security updates, Android 13+), appAccessRiskVerdict (screen capture, overlays and accessibility abuse by other apps), playProtectVerdict (Play Protect on and no dangerous apps), recentDeviceActivity (anomalously high request volume) and deviceRecall (beta). (https://developer.android.com/google/play/integrity/overview)
3. Create and link a Google Cloud project. "To integrate the API, you must have a Google Cloud project... You can then link your Google Cloud project in the Google Play Console (for apps) or the Google Play SDK Console (for SDKs). Linking your project is required" to unlock the advanced features and quota increases. You can enable Play Integrity API in the Google Cloud Console, or link first and it is enabled automatically. Watch the trap: "Projects that are enabled in the Google Cloud Console but not linked in the Play Console or Play SDK Console are not eligible for additional features." (https://developer.android.com/google/play/integrity/setup)
4. Choose standard or classic requests - they differ in latency and caching. Standard requests have the lowest latency ("a few hundred milliseconds on average") and a high reliability of obtaining a usable verdict, use smart on-device caching and delegate protection against certain attacks to Google Play; you prepare ("warm up") the token provider once - an instance "can only prepare the integrity token up to 5 times per minute" - then request a token on demand. Classic requests, the original path, have higher latency ("a few seconds on average"), initiate a fresh assessment that uses more of the user's data and battery, and leave certain mitigations to you, so they should be made "infrequently as a one-off" for a highly sensitive or valuable action. Both require Android 6.0 (API level 23) or higher. Explicit rule: "If you are considering making a classic request and caching it to use later, then you should make a standard request instead to reduce the risk of attacks." (https://developer.android.com/google/play/integrity/overview, https://developer.android.com/google/play/integrity/standard)
5. Verify on your server, never on the client. The flow is: the app prepares the token provider with your Google Cloud project number; it requests an integrity token, passing a request hash; it receives a signed and encrypted token and passes it to your backend; then "your app's backend sends the token to a Google Play server. The Google Play server decrypts and verifies the verdict, returning the results to your app's backend." Enforce the verdict only in the backend - a client-side check can be patched out. (https://developer.android.com/google/play/integrity/standard)
6. Bind tokens to the specific request. Standard requests are bound to a request hash you supply when requesting the token; classic requests use the nonce field with content binding based on request data or server-side logic. Do not cache and reuse verdicts: "Caching a verdict increases the risk of attacks such as exfiltration and replay." If you were about to cache a classic verdict for later, switch to a standard request. (https://developer.android.com/google/play/integrity/classic)
7. Respect the quota. "By default, your app can make up to 10,000 total requests per day across all installs" - you can request a higher daily maximum, but budget around it and prepare the token provider infrequently (up to 5 times per minute per instance). (https://developer.android.com/google/play/integrity/overview)
8. Roll verdicts out without breaking legitimate users. Google's explicit recommendation: "implement the API without enforcement" first, "gather telemetry and understand your audience before taking action", then estimate the impact of any enforcement you are planning and adjust your anti-abuse strategy. Treat the API as one signal, not the whole strategy: "The Play Integrity API works best when used alongside other signals as part of your overall anti-abuse strategy and not as your sole anti-abuse mechanism." The API is available across phones, tablets, foldables, Android Auto, Android TV, Android XR, ChromeOS, Wear OS and Google Play Games on PC. (https://developer.android.com/google/play/integrity/overview)